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(57) In a telecommunications system such as a glo- 
bal mobile telephone network in which each subscriber 
unit includes a Subscriber Identity Module (SIM card), 
each SIM card has fixed memory locations (22), to 
which data can be addressed over the air. The locations 
(22) can be accessed from the subscriber unit on the 
entry of short simple codes, each associated with one of 
the locations. Further fixed memory locations (24) can 
be read ever the air only when the subscriber enters a 
personal identification number. Also, the SIM contains 
means which are operable to act on receipt of a signal, 
from the user of the subscriber unit or from a host sta- 
tion, to determine and undertake an appropriate 
response to the signal. 
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Description 



This invention relates to a telecommunications sys- 
tem In particular, but not exclusively, it relates to a 
mobile communications system such as a cellular s 
mobile radio or telephone system. 

A recent innovation in such systems has been the 
introduction of Subscriber Identity Modules (SIM cards). 
These are integrated circuit cards which can be releas- 
aWy inserted into a mobile telephone and which contain 10 
in memory ttie subscriber's identity, i.e. his telephone 
number. Tnese known SIM cards also have a memory 
area which can store a certain number of alphanumeric 
characters. The memory area facilitates the so-called 
Short Message Service (SMS) in which a message for a is 

subscriber or for a specified group of subscribers can be 
broadcast over the air. as an advanced form of radiop- 
< aging. Messages can be received by a mobile tele- 
ohone whenever it is idle or during a call. However, rf a 
message is received which would overfill the memory 20 
area, data is held at the host station until such time as 
the subscriber manually clears a space for rt. 

US-A-5 127 040 describes a method and apparatus 
for remotely loading repertory telephone numbers into a 
mobile unrt Trie numbers can be recalled and used » 
later by the subscriber. 

EP-A-0 459 344 describes a method of downioaa- 
ing and executing software in a remote terminal of a 
communications system. 

WO-A-91/12698 discloses a mobile radio tele- 30 
phone having a SIM card which has been programmed 
only to authorise the use of certain services. Such pro- 
gramming takes place directly and not remotely. 

It is an object of the invention to provide a more effi- 
cient and remotely reconfigurable SIM card. 35 

According to a first aspect of the present invention 
there is provided a telecommunications system as 
claimed in claim 1. 

Making use of the invention, it is possibie tor a set 
rftdepiwenurrbets.eachwimaniderTtrryingalphanu- « 
meric tag. to be transmitted to the SIM card, allowing 
users easy access to commonly used services such as 
hotels, car hire or airline reservations. This feature is 
known as a Value Added Service Directory. 

A message may be retrievable by the subscriber on 4S 
the entry of simple, short codes into the subscriber unit 
each memory location corresponding to a particular 
code. A message may include a telephone number and. 
once stored, may be able to be overwritten over the air. 
Preferably, the or each host station is operable to trans- so 
mtt a request for information stored in a subscriber unit 
The information may be included in a message and it 
may also include information which is stored in a secure 
memory location, accessible only when the subscriber 
enters a personal identification number (PIN number), ss 
The information may include credit details relevant to 
the subscriber, for example, a credit card number of 
credit status, thus greatly facilitating credit card transac- 



tions carried out over the telephone. Using this feature 
of the invention, a credit account holder avoids having to 
dictate his account details and need only enter the man- 
datory PIN number. 

The host station may be operable to transmit 
instructions to lock and/or unlock a memory location at 
the subscriber unit, ft may be operable to transmit 
instructions to run a program stored in memory loca- 
tions at the subscriber unit. The host station may be 
operable to transmit files containing functional data 
and/or files containing non-functional data to the sub- 
scriber unit 

The messages, requests for information and the 
instructions are transmitted in a specific format which 
the subscriber unit is able to distinguish from other for- 
mats. The specific format may be made secure against 
interception. 

In a preferred embodiment, the subscriber unit 
comprises a mobile radio or telephone and an inte- 
grated circuit card which can be removably connected 
to the radiotelephone. The integrated circuit card may 
contain the memory locations and may contain means 
for distinguishing the specific format from other formate. 
The card may contain means for distinguishing between 
the messages, requests for information and instruc- 
tions The card may also contain the means for storing 
the messages and means for acting on the requests 
and instructions. 

From another aspect, the invention consists in a 
module as claimed in claim 20. 

The module may include a directory structure within 
which files can be stored. 

The invention is particularly applicable to global tel- 
ecommunication systems in which the mobile cellular 
telephone networks of various countries or areas com- 
municate using a common standard. An example of 
such a global system is GSM (Global System for Mobile 
Communications) currently operating in Europe How- 
ever the invention rs not limited to global systems and 
could be applied to a single national cellular network or 
even to a fixed land-linked network 

An embodiment of the invention will now be 
described by way of example with reference to tiie 
accompanying drawings in which:- 



Figure 1 shows the transmission of messages to a 
subscriber unit in a system according to the inven- 

Rgure 2 shows a process in which a subscriber unit 
transmits a message and requested information; 
Figure 3 is a block diagram showing elements of a 
module shown in figures 1 and 2; 
Figure 4 shows details of one of the blocks shown in 
figure 3; and 

Figure 5 is a flowchart showing the operation of tne 
module shown in figures 1 to 4. 

Figure 1 illustrates an SMS distribution path 
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according to the invention. In the prior art, the short 
messages have usually been directed to a single sub- 
scriber or a specified group of subscribers such as a 
sales term. 

However, GSM also supports a feature known as 
Cell Broadcast in which messages can be sent to all the 
subscribers in a particular area. In the embodiment of 
the invention illustrated, a message consists of the tele- 
phone number of an advertiser ad an alphanumeric tag 
to identify the advertiser. 

An operator enters the massage into a terminal 1. 
The message is then coded into a secure format knob 
as an Embedded Command Stream (ECS) ad sent via 
a mode 2 and a fixed Line 3 to a local GSM switch 4. 
According to its delivery address, the message is deliv- 
ered to any or all of the other switches within that net- 
work, or even across networks. 

The switch 4. which in this example in in the geo- 
graphical area to which the message is to be transmit- 
ted, delivers the message to a number of cellsites 5. 
The cellsites 5 are the base transceiver stations of the 
GSM network 

Each cellsite 5 then broadcasts the message to a 
group of transceivers or mobile telephones, hereinafter 
referred to as "mobiles". H Cell Broadcast is used, the 
group consists of all mobiles within the geographical 
area at the time of the broadcast. 

A selected mobile 6 receiving the message trans- 
mits a confirmation of receipt back to its respective cell- 
site 5. From now on, until an update situation, the 
system will not contact this mobile 6 again. 

The mobile 6 recognises the message as SMS data 
and passes it to a SIM card 7, which is a small self-con- 
tained microprocessor, held in a slot in the mobile 6. 
The SIM card 7 in turn recognises the ECS using spe- 
cial hardware and software and stores the message in 
memory in such a way that it may not be overwritten by 
the subscrtoer. Known SIM cards contain a large 
number of fixed memory locations in which the sub- 
scriber can store frequently dialled numbers and corre- 
sponding alphanumeric tags. The SIM card 7 of the 
invention stores the message in one of these locations, 
and then carries out a write protect operation. The loca- 
tions dedicated to storing write protected messages 
may be designated by code numbers relating to a par- 
ticular category of advertiser. Thus, for example, car 
hire company telephone numbers can be stored in loca- 
tion 01 . hotel reservations in location 02 and so on. 

Figure 2 shows a call placing process in which a 
subscriber communicates with an advertiser. The sub- 
scriber, remembering that the car hire company's 
number is in location 01 as shown at 8. keys in a short 
code corresponding to the location, such as 01 #. The 
mobile 6 then interrogates the SIM card 7 to retrieve the 
telephone number from the location. The SIM card 7 
provides both the number and the alphanumeric tag giv- 
ing the corrpany's name and displays it to the sub- 
scriber. The user confirms that he wishes to proceed by 



pressing SEND. 

Next, the mobile obtains a voice channel through 
which the call proceeds to the dialled number. The GSM 
system automatically handles intra-network and inter- 
5 network hops. At this point the subscrtoer can hold a 
voice conversation with the company. 

Providing the correct equipment has been installed 
at the company, as soon as the call is answered, sub- 
scriber identity information read from the SIM card 7 
10 gives the company immediate customer billing details 
such as a name and address. 

The SIM card 7 also contains information detailing 
the subscrtoer's credit account. This information is held 
in a separate, secure memory location, accessible only 
15 when the subscriber enters a mandatory PIN number, 
known only to himself, thus confirming that the mobile 
has not been stolen or lost When the subscriber has 
confirmed his car hire deal, he enters the PIN number 
into the mobile 6. requesting the credit information from 
20 the SIM card 7. The SIM card 7 supplies the information 
and the mobile uses existing voice/data techniques to 
transmit the information to the company, in a format 
secure against detection by fraudsters. The sale is con- 
firmed by the company or its equipment and the call is 

25 terminated. 4 , 

In this exanple. it is also possible to obtain a tele- 
phone or fax number from the operator-assisted direc- 
tory enquiries system without the subscriber having to 
manually enter the number into the communications ter- 
30 minal which he desires to use. 

To use this feature, the subscriber calls network 
directory enquiries and gives the name of the person, 
company or service of which he wishes to ascertain the 
telephone nurrtier, as well as any additional information 
35 requested by the operator answering the call. The oper- 
ator then locates the number, confirms it and enquires 
as to whether the number is to be transmitted verbally, 
transferred over SMS into a given memory location of 
the subscriber's SIM card or both. 
40 If the subscriber chooses a SIM update, the voice 
call is terminated and the operator initiates the SMS 
process by entering a sequence into a computer or 
pressing a dedicated button. The telephone number ts 
then encoded into an ECS message at the despatch 
46 centre and is posted across the network to the sub- 
scribers communications terminal, which transmits a 
confirmation to the despatch centre. Thus the retry 
mechanism, which operates until such a confirmation is 
received, is suspended. 
so The communications terminal recognises the mes- 
sage as SMS data, passes it to the SIM card, and if 
capable, displays a -message received" banner. The 
SIM card in turn recognises the ECS using special hard- 
ware and software, and decodes it accordingly. The 
55 number, and any associated alphanumeric tag. which 
would normally consist of the name of the person or 
company, are recovered together with the memory loca- 
tion in which they are intended to be stored. The 
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nurrtoer and name-tag are then written to that location 
and are write-protected if requested by the subscriber, 
the overwrite protection being encoded into the mes- 
sage at source. 

Subsequently, the subscriber attempts to place a 
call to the nurrtoer in the known memory location by key- 
ing in the memory location number. The SIM card 
passes the telephone or fax number to the communica- 
tions terminal on demand, and upon receipt of the sub- 
scriber's confirmation, the communications terminal 
sets up the call to the desired number. 

Figure 3 shows the electronic structure of the SIM 
card 7. The card communicates with the mobile to which 
it is connected via an input/output (I/O) manager 15, 
preferably using the protocol ISO 7816 T=0. A filter 16 
receives incoming data from the I/O manager and 
detects any ECS messages from among the short mes- 
• sages received. The ECS messages are sent directly to 
an extended erasable read only memory (E 2 ROM) 17, 
which is preferably a "flash- E 2 ROM. Data can also be 
output from the E 2 ROM directly to the I/O manager 15. 
■me remaining blocks shown in figure 3 are standard 
components of a SIM card. . J _ 

Figure 4 shows how the E 2 ROM is organised. A 
root directory 18 contains a SIM administration and 
identif ier 19, a GSM directory and network data 20, and 
a telecom directory 21. 

The telecom directory in turn contains memory 
locations as follows: "abbreviated dial numbers" 22. 
"capability configuration" 23, "short messages" 24, 
"fixed dial nurrtbers" 25, and "charging counter 26. 
Each block represents a plurality of memory locations. 
The frequently dialled nunbers and corresponding 
alphanumeric tags are stored at locations 22. 

The "abbreviated dial numbers" locations 22 and 
the "short messages" locations 24 each have an asso- 
ciated locking control file 27. 28 respectively. The lock- 
ing control files constitute means for read/write 
protecting and removing read/write protection from their 
associated memory locations. The locking control files 
27 28 will typically be in the telecom directory 21 as 
shiwn, however they can be located elsewhere such as 
in an administration directory. 

Figure 5 is a flowchart illustrating the operation of 
the SIM card 7, which uses the specially fabricated 
hardware and software which has been described 
above to irrplement the operations illustrated. At loz- 
enge 9, messages, requests, and instructions having 
ECS are distinguished from those without. Each of 
these ECS types consists of a data stream headed by a 
command which is one of at least four types: write com- 
mands for the messages, read commands for the 
requests for information, attribute commands for lock or 
unlock instructions and run commands for instructions 
to run a program. 

The command and data types are decoded at box 
10 and acted on in one of the four paths 11-14. 

Path 1 1 handles the write commands to store mes- 



sages starting at a location specified therein. Path 12 
handles the read commands; again, the requests for 
information contain a location to be accessed first Suc- 
cessive locations are read and the data stored in a 
5 buffer until the required amount of data has been read. 
The data in the buffer is then encoded into the ECS for- 
mat and despatched from the mobile using SMS to the 
calling party. 

In path 13, attrfoute commands are used to lock or 
io unlock specified memory locations ad render them 
accessible or inaccessible, either to calling parties or to 
the sitoscriber. In path 14, run commands cause a pro- 
gram stored in the SIM card to be run. 

The basic ECS system is expandable to up to 255 
15 internal shell commands of which write, read, 
lock/unlock and run are four examples. The specific pro- 
tocol used for the transfer of information is not fixed and 
could be IS07816 T=0 or any other suitable protocol. 
The internal shell commands are a supplement to 
20 the ability of the system to create external file objects 
within the SIM card 7. The file objects are of two types: 
Application Data File Programs (ADFP's) containing 
functional data which can be executed by the SIM card 
processor and can self modify « required and Applica- 
26 tion Data Files (ADFs) containing non-functional data 
which does not have these capabilities. Existing 
ADF(P)'s can be modified over-the-air enabling 
advanced facilities such as personalisation, re-person- 
alisation or downloadable phone book. 
so The SIM card 7 has a directory structure, similar to 
that of a computer disk, and new ADF(P)'s can be 
downloaded into any directory over the air. Also over the 
air. drectories can be created, deleted and modified, 
multiple tree directory operations can be carried out and 
35 ADF(P)'s that are no longer required can be deleted 
The amount of ADF(P) data which can be downloaded 
is limited only by the size of the E 2 R0M memory of the 

^The invention, as descrtoed, greatly extends the 
40 applications of SIM cards. For example, using the Value 
Added Services Directory, sibscribers can book hotels 
and airline seats over their mobiles quickly ad easily. 

An additional advantage of this feature of invention 
is that the geographical distribution of messages to 
as cards in a specific area such as the South of Franco is 
facilitated. Thus advertisers can direct their messages 
to all mobile subscribers in the specific area. This is, 
particularly useful when subscribers "roam" from one 
area to another and have no knowledge of local serv- 
so ices. 

The directory enquiries download enables contact 
telephone or fax numbers to be delivered to a sub- 
scriber's communications terminal without any interven- 
tion by the subscriber. The process of manually entering 

55 a number whilst engaged in a call to the operator is 
often dangerous, especially when the subscriber is dnv- 

1,19 The ability of the system to download ADF(P)*s 
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means that additional services can be added to the SIM 
card over the air while maintaining total compatibility 
with the existing cellular system. Thus the SIM card 
could acquire the functions of a credit card, passport, 
driving licence, car park pass, membership card and so 
on becoming a multiservice card. Also, dynamically 
updatable services can be added which require a differ- 
ent process to be run each time a service is accessed. 

Once the card has extra service on it, it can be used 
outside of the mobile phone environment if desired as a 
standalone item. This can be read from or written to by 
a dedicated piece of hardware, such as a point of sale 
machine. If desired, the new services can be deleted, 
however the card will never lose its mobile phone SIM 
capability. In addition, if the card has extra services, 
they will continue to function even if the subscriber has 
been disconnected from the mobile phone network, 
unless otherwise desired. 

Modifications are posstole without departing from 
the scope of the invention. 

For exarrple. the SIM card can be trained only to 
receive messages detailing services relevant to the sub- 
scriber's needs. 

Claims 

1 A telecommunications system comprising at least 
one host station (1) and a plurality of subscriber 
units (6) , each of which has a multiplicity of memory 
locations, the or each host station being operable to 
transmit a message to at least one of the subscriber 
units, characterised in that 

said message is coded in a specific format 
distinguished from other formats used in the system 
and conprises a data stream inclufing a command 
which is one of at least a write command for writing 
data to a selected memory location, a read com- 
mand for requesting data stored in the subscriber 
unit, an attribute command to enable or prohibit a 
selected memory location to be overwritten or to be 
read from the or each host station or the subscriber 
unit, and a run command for executing functional 
data stored at a selected memory location; and in 
that 

each subscriber unit has means for detect- 
ing a message coded in said specific format (16), 
means for decoding said message, and means 
responsive to said commands to determine and 
undertake appropriate processing of the associated 
data. 

2. A system according to claim 1 , wherein each sub- 
scriber unit (6) includes access means enabling 
said memory locations (17) to be selectively 
accessed, when required, to fetch from a selected 
memory location the data stored therein. 



scriber unit (6) includes means to present informa- 
tion corresponding to the fetched data to a user of 
the subscriber unit. 

5 4. A system according to daim 2 or 3. wherein each 
subscriber unit (6) includes means to transmit the 
fetched data to said at least one host station (1). 

5. A system according to claim 3 or 4, wherein each 
10 subscriber unit (6) includes means adapted to 

transmit said data as a second message coded in 
said specific format 

6. A system according to claim 5, wherein the data is 
15 fetched from successive memory locations (1 7), is 

buffered, coded in said specific format and, thereaf- 
ter, transmitted. 

7. A system according to daim 2, 3, 4, 5 or 6, wherein 
20 the memory locations (17) include memory loca- 
tions identified by short codes, and including means 
responsive to the entry of a selected short code by 
the access means to fetch the data from the corre- 
sponding memory location. 

25 8. A system according to claim 7, wherein said short 
codes are abbreviated dial number codes. 

9. A system according to any preceding claim 2 to 8, 
so wherein each subscriber unit (6) includes a send 

means for instigating dialling of a telephone number 
contained in the fetched data and. in response to a 
dialled call to said telephone number being 
answered, data is fetched from a predetermined 
35 memory location of said multiplicity of memory 
locations (17) and sent to receiving equipment 
associated with said telephone number. 

10. A system according to claim 2 to 9. wherein the 
40 memory locations (17) include secure memory 

locations and the access means is only able to fetch 
data from a Secure location in response to the entry 
of a personal identification signal into the sub- 
scriber unit (6). 

45 11. A system according to any preceding claim, 
wherein said messages are coded in a secure for- 
mat 

so 12. A system as claimed in claim 11, wherein the 
secure format is in the form of an embedded com- 
mand stream. 

13. A system according to any preceding claim, 
55 wherein said messages are transmitted using a 
short message service. 



3. 



A system according to daim 2. wherein each sii>- 14. A system acceding to any preceding claim. 



5 



EP 0 865 217 A2 



10 



wherein the messages carry executable application 
data file programs for providing each subscnber 
unit (6) with additional services. 

15 A system according to any preceding claim, 
' wherein the memory locations (17) have file han- 
dling capabilities including directory functions. 

16. A system according to daim 15, wherein data 
related to said attribute commands is stored in lock- 
ing control files (27,28) within predetermined direc- 
tories. 

17. A system according to any preceding claim which is 
a cellular radio communication system. 

18 A system according to claim 17. including means 
» for transmitting the messages simultaneously to 
more than one subscriber unit (6) via cell broad- 
casting. 

19. A system according to any preceding daim. 
wherein the memory locations (17), detecting and 
decoding means and means responsive to the 
commands are comprised in an integrated arcurt 
module or card C7) removably connected to each 
subscriber unit (6). 

2a A module (7) for controlling a subscrtoer unit (6) in 
a telecommunications system including at least one 
host station (1) operable to transmit a message to 

the module, said module being adapted to be 
removably connected to the subscriber unit and 
comprising a multiplicity of memory locations (17), 
characterised in that 

said module comprises means for detecting 
messages transmitted thereto, and coded in a spe- 
cific format distinguished from other formats used in 
the system, each said message comprising a data 
stream including a command which is one of at 
least a write command for writing date to a selected 
memory location, a read command for requesting 
data stored at a selected memory location, an 
attribute command to enable or prohibit a selected 
memory location to be overwritten or to be read 
from the or each host station or the subscriber unit, 
and a run command for executing functional data 
stored at a selected memory location; and in that 

said module further comprises means for 
decoding said messages and means responsive to 
said commands to determine and undertake appro- 
priate processing of the data contained in the mes- 
sage 

21 A module (7) according to daim 20, including read 
* means operable to fetch data stored in the memory 
locations and transmit the data stored in a selected 
memory location to the associated subscrtoer unit 



22. A module (7) according to claim 21, wherein the 
read means is adapted to transmit said data as a 
second message coded in said specific format 

s 23. A module (7) according to claim 21 or 22, wherein 
the read means is responsive to a personal identifi- 
cation signal entered into the assodated subscriber 
unit (6). 

10 24. A module (7) according to claim 21. 22 or 23. 
wherein the memory locations (17) are identified by 
short codes and the module includes means 
responsive to short codes to transmit data from the 
selected memory location. 



25. A module (7) according to any preceding claim 20 
to 24. including a directory structure for addressing 
the memory locations. 

20 26. A module (7) according to any preceding claim 20 
to 25. which is programmable for use away from the 
subscriber unit by downloading extra services onto 
it, via said at least one host station, prior to remov- 
ing it from the subscriber unit 

27. A module (7) according to any preceding claim 20 
to 26, wherein the module is in the form of an inte- 
grated drcuit card. 
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